<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Thoughts on PatchGuard (otherwise known as Kernel Patch Protection)</title>
	<atom:link href="http://www.nynaeve.net/index.php?feed=rss2&#038;p=111" rel="self" type="application/rss+xml" />
	<link>http://www.nynaeve.net/?p=111</link>
	<description>Adventures in Windows debugging and reverse engineering.</description>
	<lastBuildDate>Tue, 24 Aug 2010 12:05:39 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Samuel Bronson</title>
		<link>http://www.nynaeve.net/?p=111&#038;cpage=1#comment-66870</link>
		<dc:creator>Samuel Bronson</dc:creator>
		<pubDate>Fri, 18 Jun 2010 19:19:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=111#comment-66870</guid>
		<description>I don&#039;t really see how the hyperviser thing can actually stop kernel patching -- what&#039;s to prevent simply changing the on-disk PE image? I guess it would put a stop to the typical frivolous hotpatching that AV products do, though...</description>
		<content:encoded><![CDATA[<p>I don&#8217;t really see how the hyperviser thing can actually stop kernel patching &#8212; what&#8217;s to prevent simply changing the on-disk PE image? I guess it would put a stop to the typical frivolous hotpatching that AV products do, though&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alienrancher</title>
		<link>http://www.nynaeve.net/?p=111&#038;cpage=1#comment-2165</link>
		<dc:creator>alienrancher</dc:creator>
		<pubDate>Tue, 06 Feb 2007 22:41:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=111#comment-2165</guid>
		<description>well, if Cutler did this aberration called PG it goes to show that doctors can get sick too.</description>
		<content:encoded><![CDATA[<p>well, if Cutler did this aberration called PG it goes to show that doctors can get sick too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Skywing</title>
		<link>http://www.nynaeve.net/?p=111&#038;cpage=1#comment-1978</link>
		<dc:creator>Skywing</dc:creator>
		<pubDate>Thu, 01 Feb 2007 17:54:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=111#comment-1978</guid>
		<description>As far as I know, Dave Cutler was indeed involved in the development of PatchGuard.</description>
		<content:encoded><![CDATA[<p>As far as I know, Dave Cutler was indeed involved in the development of PatchGuard.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nksingh</title>
		<link>http://www.nynaeve.net/?p=111&#038;cpage=1#comment-1955</link>
		<dc:creator>nksingh</dc:creator>
		<pubDate>Thu, 01 Feb 2007 04:51:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=111#comment-1955</guid>
		<description>The way this system works (based on your Uninformed article about the self-decrypting execution stub) is quite a bit cleverer than something running in kernel mode should be, from a reliability standpoint. 

I wonder about one thing:  do you think Dave Cutler wrote this code himself?  He did spend a couple of years &quot;getting NT ported to x64 hardware,&quot; so I could guess that this would be under his purview.  I don&#039;t know how big the core group who do the Executive and HAL are, but I have some doubts that there would be a ton of people who have the authority and stature to get such dangerous code included into a shipping kernel.  Maybe I&#039;m just hero-worshipping.   

Thanks for the good post.</description>
		<content:encoded><![CDATA[<p>The way this system works (based on your Uninformed article about the self-decrypting execution stub) is quite a bit cleverer than something running in kernel mode should be, from a reliability standpoint. </p>
<p>I wonder about one thing:  do you think Dave Cutler wrote this code himself?  He did spend a couple of years &#8220;getting NT ported to x64 hardware,&#8221; so I could guess that this would be under his purview.  I don&#8217;t know how big the core group who do the Executive and HAL are, but I have some doubts that there would be a ton of people who have the authority and stature to get such dangerous code included into a shipping kernel.  Maybe I&#8217;m just hero-worshipping.   </p>
<p>Thanks for the good post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fareed Rizkalla</title>
		<link>http://www.nynaeve.net/?p=111&#038;cpage=1#comment-1915</link>
		<dc:creator>Fareed Rizkalla</dc:creator>
		<pubDate>Wed, 31 Jan 2007 08:26:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=111#comment-1915</guid>
		<description>How can someone protect something which lies under a cover!?
If he even doesn&#039;t know what it is ; )</description>
		<content:encoded><![CDATA[<p>How can someone protect something which lies under a cover!?<br />
If he even doesn&#8217;t know what it is ; )</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.333 seconds -->
